Impact
An argument ID in sup_edit1.php can be manipulated to execute arbitrary SQL statements against the database via SQL injection. The flaw is identified as CWE-74 and CWE-89.
Affected Systems
itsourcecode Sales and Inventory System version 1.0.
Risk and Exploitability
The CVSS score is 5.3 and the EPSS score is below 1%, indicating a low exploitation probability. The flaw can be exploited remotely through the web interface, and it has been publicly disclosed, allowing attackers to construct payloads. Because the vulnerability is not listed in KEV, the risk is considered moderate at this time.
OpenCVE Enrichment